107 lines
7.7 KiB
Markdown
107 lines
7.7 KiB
Markdown
---
|
||
title: aquasecurity/trivy-action — GitHub Actions Official README
|
||
source_type: official-doc
|
||
url: https://github.com/aquasecurity/trivy-action
|
||
archive_url:
|
||
related_branches: [feature-dependency-vulnerability-management-contract]
|
||
related_projects: []
|
||
tags: [official-doc, ci-cd, docker, slsa]
|
||
created: 2026-06-15
|
||
---
|
||
|
||
# aquasecurity/trivy-action — GitHub Actions Official README
|
||
|
||
> Layer: `raw/` — 외부 자료(공식 문서 / 대기업 기술 블로그)의 **원문 발췌·출처 기록**.
|
||
> 검증된 요약은 `/ingest` 후 `wiki/concepts/`에 `source-summary-template` 형식으로 별도 작성. 원본은 raw에 영구 보관.
|
||
|
||
## Parent / 활용 branch (필수, 최소 1개+)
|
||
|
||
| Branch | 이 자료가 정당화하는 결정 |
|
||
|---|---|
|
||
| [[raw/branch-notes/feature-dependency-vulnerability-management-contract]] | D1/게이트 — Trivy를 GitHub Actions CI에서 release-blocking 게이트로 구성하는 방법(exit-code + severity 임계값), 그리고 suppression 파일(`trivyignores:`) 파라미터 |
|
||
|
||
## 출처 / Source
|
||
|
||
- 원본 URL: https://github.com/aquasecurity/trivy-action
|
||
- 아카이브 URL:
|
||
- 저자 / 조직: Aqua Security (aquasecurity)
|
||
- 발행일: (리포지터리 README, 지속 갱신 — 확인 시점 기준 v0.36.0)
|
||
- 마지막 확인일: 2026-06-15
|
||
|
||
## 왜 저장했는지 / Why archived
|
||
|
||
`aquasecurity/trivy-action` 의 공식 README 는 GitHub Actions CI 에서 `exit-code: '1'` + `severity: 'CRITICAL,HIGH'` 조합으로 취약점 발견 시 빌드를 실패시키는 release-blocking 게이트 구성의 **유일한 공식 출처**다. `trivyignores` 파라미터를 통한 suppression 파일 지정 방법도 동일 문서에서 확인 가능하므로 보관한다.
|
||
|
||
## 핵심 인용 / Key quotes (verbatim, 3~5문장)
|
||
|
||
> [§Scan CI Pipeline / inputs table] `| \`exit-code\` | String | \`0\` | Exit code when specified vulnerabilities are found |`
|
||
> (inputs 표, line 877 of fetched README)
|
||
|
||
> [§Scan CI Pipeline — 예제 YAML, lines 57–60]
|
||
> ```yaml
|
||
> exit-code: '1'
|
||
> ignore-unfixed: true
|
||
> vuln-type: 'os,library'
|
||
> severity: 'CRITICAL,HIGH'
|
||
> ```
|
||
|
||
> [§Scan CI Pipeline (w/ Trivy Config) — fs 모드 예제, line 83]
|
||
> ```yaml
|
||
> scan-type: 'fs'
|
||
> scan-ref: '.'
|
||
> trivy-config: trivy.yaml
|
||
> ```
|
||
|
||
> [§inputs table, line 889] `| \`trivyignores\` | String | | comma-separated list of relative paths within the repository to one or more \`.trivyignore\` files, or a single \`.trivyignore.yaml\` file. |`
|
||
|
||
> [§Skipping Setup when Calling Trivy Action multiple times — 예제 YAML, lines 270–279]
|
||
> ```yaml
|
||
> - name: Fail build on High/Criticial Vulnerabilities
|
||
> uses: aquasecurity/trivy-action@v0.36.0
|
||
> with:
|
||
> scan-type: "fs"
|
||
> format: table
|
||
> scan-ref: .
|
||
> severity: HIGH,CRITICAL
|
||
> ignore-unfixed: true
|
||
> exit-code: 1
|
||
> ```
|
||
|
||
## Claims Extracted / 추출된 주장
|
||
|
||
| Claim ID | Claim (이 자료가 직접 말하는 것) | Evidence quote | Strength | Applies to | Does not prove |
|
||
|---|---|---|---|---|---|
|
||
| C1 | `exit-code` input 의 기본값은 `0` 이며, 지정된 취약점이 발견됐을 때 종료하는 exit code 를 설정한다 | [§inputs] `Exit code when specified vulnerabilities are found` (default `0`) | `official-vendor-doc` | `aquasecurity/trivy-action` 모든 scan-type | exit-code=1 이 실제로 CI runner 에서 step 실패를 유발하는지 (runner OS 정책에 따라 다를 수 있음) |
|
||
| C2 | `exit-code: '1'` + `severity: 'CRITICAL,HIGH'` 조합이 공식 README 의 release-blocking 예제로 제시된다 | [§Scan CI Pipeline] `exit-code: '1'` / `severity: 'CRITICAL,HIGH'` (lines 57, 60) | `official-vendor-doc` | image scan, fs scan, config scan 모두 동일 파라미터 조합 사용 가능 | 해당 severity 기준이 모든 조직의 보안 정책에 충분한지 여부 |
|
||
| C3 | `scan-type` 은 `image`, `fs`, `repo`, `config`, `rootfs` 등 다양한 값을 지원하며, image 와 fs 스캔을 동일 action 으로 처리할 수 있다 | [§inputs] `Scan type, e.g. \`image\` or \`fs\`` (line 869); fs 예제 line 83 | `official-vendor-doc` | `aquasecurity/trivy-action` 전체 | scan-type 별 세부 동작 차이(예: repo vs fs 의 git history 포함 여부)는 이 README 만으로 완전히 증명 안 됨 |
|
||
| C4 | `trivyignores` 파라미터는 리포지터리 내 상대 경로로 `.trivyignore` 파일 또는 단일 `.trivyignore.yaml` 파일을 comma-separated 로 지정할 수 있다 | [§inputs] `comma-separated list of relative paths within the repository to one or more \`.trivyignore\` files, or a single \`.trivyignore.yaml\` file.` (line 889) | `official-vendor-doc` | `aquasecurity/trivy-action` 의 suppression 구성 | `.trivyignore` 파일 내부 문법(CVE ID 형식, 이유 주석 포맷 등)은 별도 Trivy 공식 문서 참조 필요 |
|
||
| C5 | 옵션 우선순위는 GitHub Action flag > Environment variable > Config file > Default 순이다 | [§Order of preference for options] `GitHub Action flag / Environment variable / Config file / Default` (lines 104–107) | `official-vendor-doc` | `trivy-config` (`trivy.yaml`) 와 action inputs 혼용 시 | 이 우선순위가 미래 버전에서도 동일하게 유지된다는 보장은 현재 문서로 증명 불가 |
|
||
|
||
## Usage Boundaries / 적용 경계
|
||
|
||
- 이 자료가 직접 증명하는 것:
|
||
- `C1`, `C2`: `exit-code: '1'` 과 `severity: 'CRITICAL,HIGH'` 를 action input 으로 설정하면 해당 severity 취약점 발견 시 GitHub Actions step 이 exit code 1 로 종료됨 — 공식 README 가 직접 release-blocking 패턴으로 제시한 예제
|
||
- `C3`: 동일 action(`aquasecurity/trivy-action`)으로 image 스캔과 fs(filesystem) 스캔 모두 처리 가능. `scan-type` 파라미터로 구분
|
||
- `C4`: `.trivyignore` 파일 경로를 `trivyignores:` 파라미터로 action 에 전달하는 방법
|
||
- `C5`: `trivy.yaml` config 파일보다 action inputs 가 우선한다는 우선순위 계층
|
||
- 이 자료가 증명하지 않는 것:
|
||
- Trivy 내부 CVE DB 의 정확성 또는 갱신 주기
|
||
- `.trivyignore` 파일 내 suppression 엔트리 문법(별도 Trivy 공식 docs 필요)
|
||
- 특정 언어/런타임 생태계에서 false positive 비율
|
||
- SARIF 업로드 후 GitHub Security tab 에서의 실제 표시 동작
|
||
- 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
|
||
- `exit-code: '1'` 이 실제 프로젝트 CI runner (ubuntu-24.04) 에서 step failure 로 올바르게 전파되는지 로컬 검증 필요
|
||
- `trivyignores:` 에 지정할 `.trivyignore` 파일 경로가 실제 리포지터리 구조와 일치하는지 확인
|
||
|
||
## 메모 / Notes
|
||
|
||
- 현재 최신 pin 버전: `aquasecurity/trivy-action@v0.36.0` (README 상 기준, 실제 사용 시 최신 릴리즈 확인 권장)
|
||
- `ignore-unfixed: true` 는 패치가 없는 취약점을 스킵하므로, false positive 노이즈 감소에 유효하지만 unfixed 취약점을 visibility 에서 제외한다는 trade-off 존재
|
||
- SARIF 포맷 + `github/codeql-action/upload-sarif@v4` 조합은 GitHub Advanced Security 라이선스 필요 — 프라이빗 repo 무료 플랜에서는 사용 불가 (README §"Using Trivy if you don't have code scanning enabled" 참조)
|
||
|
||
## Related / 관련
|
||
|
||
- Trivy 공식 문서 (config file 문법, `.trivyignore` 형식): https://aquasecurity.github.io/trivy/latest/docs/references/configuration/config-file/
|
||
- Trivy 환경 변수 레퍼런스: https://aquasecurity.github.io/trivy/latest/docs/configuration/#environment-variables
|
||
- 이 자료를 인용한 wiki 요약: `[[wiki/concepts/trivy-ci-gate]]` (생성 시)
|